package com.syg.Commons.Filter;

import javax.servlet.Filter;
import javax.servlet.FilterChain;
import javax.servlet.FilterConfig;
import javax.servlet.ServletException;
import javax.servlet.ServletRequest;
import javax.servlet.ServletResponse;
import javax.servlet.http.HttpServletRequest;
import java.io.IOException;

/**
 * 防止Xss攻击
 */
//@Configuration
//@Order(1) //表示执行顺序,值越小,越先执行(由Spring提供)
//@WebFilter(filterName = "XssFilter", urlPatterns = "/*") //相当于web.xml中的配置 (由tomcat提供)
public class XssFilter implements Filter {
    @Override
    public void init(FilterConfig filterConfig) throws ServletException {

    }

    @Override
    public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain) throws IOException, ServletException {
        XssRequestWrapper xssReq = new XssRequestWrapper((HttpServletRequest) request);
        xssReq.filterXSS();
        chain.doFilter(xssReq, response);
    }

    @Override
    public void destroy() {

    }
}
